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Abstract 

Formal methods are a nice idea, but the size and complexity of real systems means that they are impractical 
We propose that a reasonable alternative to attempting to specify and verify the system in its entirety is to bu 
and evaluate an abstract model(s) of aspects of the system that are perceived as important. Using a model v 
not provide proof of the system, but it can help to find shortcomings and errors at an early stage. Executing tl 
model should also give a measure of confidence in the final product. Many systems today are built from 
communicating components so that the task of the developers is becoming fitting these components togethe 
to form the required system. We show how a formal model can be sympathetic to this type of architecture us 
our tool, RolEnact and explain how this may be related to a COM implementation 
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